@@ -367,3 +367,25 @@ username. A final force-blocking dashboard run returned all 14 insights without
367367error: one product install, ten active installations, four searches across two
368368installations, one show, the expected lifecycle outcome rows, and six sanitized
369369exceptions affecting four disposable installations.
370+
371+ ## Lockfile hygiene review
372+
373+ A final P3 review correctly identified that the telemetry branch had retained a
374+ revision-2 lockfile generated by local ` uv 0.6.16 ` , while current main uses
375+ revision 3. The raw ` uv.lock ` diff was 568 additions and 509 deletions even
376+ though its normalized dependency change was only PostHog and four transitive
377+ packages.
378+
379+ Modern ` uv ` preserves an existing compatible lock revision, so rerunning it on
380+ the branch's revision-2 file was insufficient. The lock was mechanically seeded
381+ from current main and regenerated with ` uv 0.11.29 ` . The resulting revision-3
382+ lock keeps ` upload-time ` metadata and differs from main by exactly 59 additions,
383+ with no deletions: ` posthog ` , ` backoff ` , ` distro ` , ` requests ` , ` urllib3 ` , and the
384+ two CodeAlmanac PostHog dependency edges.
385+
386+ Both modern and repository-local ` uv lock --check ` pass. Modern locked sync
387+ dry-run and local ` uv sync --locked ` make no changes. The exact lock passes all
388+ 564 tests on Python 3.12.10 and Python 3.13.3, Ruff, 71-page Almanac validation,
389+ ` git diff --check ` , and a clean modern-uv sdist/wheel build. No project-wide uv
390+ pin was added because that is a separate tooling-policy decision; the review
391+ noise is removed without broadening this telemetry fix.
0 commit comments